Networking
OSI, TCP/IP, packet analysis, routing. Every other skill builds on this.
Every skill that matters in 2026, organized into 5 domains. Click any skill for modules, certifications, and adjacent skills. Pick a career path to highlight your route.
Every skill below links to academy modules and the certifications that signal it. Click for details.
OS, networking, crypto, scripting — every other skill builds on these.
OSI, TCP/IP, packet analysis, routing. Every other skill builds on this.
Linux fundamentals, permissions, services, hardening.
Windows security model, event logs, hardening.
Symmetric/asymmetric primitives, TLS, PKI, secrets mgmt.
Python, PowerShell, Bash. Every security role relies on scripting to scale. OSINT automation, exploit dev, detection engineering, IR all build on this.
Entry-level IT support. Ticketing systems, user troubleshooting, asset management. Most common first role feeding into security + admin careers.
Linux system administration — users, services, filesystems, package management, shell scripting, performance tuning. Foundation for cloud + DevOps + SRE careers.
Windows Server administration — AD, Group Policy, Exchange, SCCM, PowerShell automation, patch management. Pathway to AD security + Microsoft cloud careers.
macOS fleet management — MDM (Jamf/Kandji/Addigy), identity integration, endpoint compliance. Growing niche in modern enterprises with mixed fleets.
Network engineering — routing, switching, firewalls, VLANs, SD-WAN, load balancing. Solid base for network security + cloud networking careers.
Database operations — schema, performance tuning, backup/recovery, replication, security. Feeds into data security + cloud database roles.
Adversary mindset, exploitation craft, red-team operations.
Nmap, Burp, Metasploit — the classic pentesting toolkit.
Full web application exploitation from HTTP basics to advanced classes.
Android + iOS pentesting with Frida/Objection, defeating hardening.
Kerberos abuse, BloodHound, Golden/Silver tickets, hybrid pivots.
Adversary simulation — initial access, C2, lateral movement, EDR evasion.
API-layer security: OWASP API Top 10, auth, GraphQL, rate limiting.
Open-source intelligence: Shodan, Censys, crt.sh, subdomain enumeration, GitHub dorking, dark-web research. 60-80% of CTI value at zero cost.
Binary analysis with Ghidra, IDA, radare2. Malware RE, exploit research, red team tool development, threat research.
Writing custom exploits from vulnerability discovery. Heap feng shui, ROP, shellcoding, kernel exploitation. The deepest offensive skillset.
Wireless security: WPA3 attacks, captive-portal abuse, Wi-Fi deauth, 802.1x bypass, Bluetooth Low Energy attacks.
Detection engineering, threat hunting, incident response, forensics.
SOC operations, SIEM, Sigma rules, EDR telemetry.
OSINT, Pyramid of Pain, MITRE ATT&CK, intel-driven hunting.
Digital forensics, incident response, memory + malware analysis.
Defender track — detections, response, hardening.
Security in the SDLC — SAST/DAST, IaC, pipelines, supply chain.
Prompt injection, model theft, data poisoning, adversarial ML, LLM supply chain. Fast-growing field.
Identity and Access Management at scale: SSO, MFA, federation, privileged access, lifecycle. The new perimeter.
Architecture where every request is authenticated and authorized regardless of origin. BeyondCorp, SDP, ZTNA.
Host, memory, and network forensics. Evidence chain of custody, timeline analysis, artifact recovery.
Secure-by-design coding practices, threat modeling at story level, secure code review, safe defaults.
Scanner operations, vulnerability triage, patching SLAs, risk-based prioritization. Defensive operational backbone.
Site Reliability Engineering — observability, SLOs, incident response, capacity planning, automation. Bridge between ops + dev with strong security relevance.
AWS / Azure / GCP, Kubernetes, IT infrastructure administration.
AWS security: IAM, S3, cross-account, incident response.
Entra ID, Azure resources, M365 security.
GCP IAM, VPC-SC, Workload Identity Federation.
Container + Kubernetes security.
IoT devices + industrial control systems. Safe OT testing.
Cloud infrastructure operations — IaaS, networking, storage, cost, automation. Natural pathway to cloud security specialization.
DPDP / ISO 27001 / SOC 2, vuln mgmt, sec architecture, leadership.
Governance, risk, compliance. ISO 27001, SOC 2, audits.
DPDP Act, consent, breach response, privacy practitioner path.
Management track for senior roles — CISO, director of security.
Enterprise security architecture. Reference patterns, threat modeling, control frameworks. Senior IC + leadership blend.
No skills match your filter. Try a different search or click "Show all".
Each path shows a 5-level skill progression. Basic → Intermediate → Advanced → Expert → Extreme. Click a path to expand it — one opens at a time.
Basic Networking + Linux → Intermediate Scripting + Pentest → Advanced Web + AD → Expert API + WiFi → Extreme OSCP-level. 18-24 months.
Basic Net + OS → Intermediate Scripting + Pentest → Advanced AD + Web → Expert Red Team Ops → Extreme Exploit Dev. 3-5 years.
Basic Net + OS → Intermediate Scripting + SOC → Advanced Threat Intel → Expert DFIR + Forensics → Extreme Blue Team lead. 3-4 years.
Basic Linux/Windows → Intermediate Scripting + SOC → Advanced DFIR + Forensics → Expert Reverse Engineering → Extreme Threat Intel.
Basic Web fundamentals → Intermediate Web Pentest → Advanced API + Secure Coding → Expert DevSecOps → Extreme Crypto architecture.
Basic Net + Crypto → Intermediate IAM + AWS → Advanced Azure/GCP → Expert K8s + DevSecOps → Extreme Zero Trust.
Basic Linux → Intermediate Scripting → Advanced Pentest + Binary Analysis → Expert Reverse Engineering → Extreme Custom exploits.
Basic AI fundamentals → Intermediate Web Pentest + Secure Coding → Advanced AI Security → Expert Threat Intel on AI → Extreme GRC for AI.
Basic Technical anchor → Intermediate GRC fundamentals → Advanced Sec Architecture → Expert Zero Trust → Extreme Mgmt + Board.
Basic Net + Crypto → Intermediate GRC + DPDP → Advanced Vuln Mgmt → Expert Sec Architecture → Extreme Mgmt. CISA + CISSP.
Basic Ticketing + support → Intermediate OS basics → Advanced Networking → Expert Scripting + automation → Extreme Pivot to specialist. 6-18 months.
Basic FS + users → Intermediate Shell + packages → Advanced Network services + hardening → Expert SRE practices → Extreme Cloud at scale. LPIC, RHCE.
Basic Server basics → Intermediate AD + GPO → Advanced PowerShell → Expert Exchange / SCCM / Intune → Extreme Azure / Entra. AZ-104, MCSE.
Basic macOS support → Intermediate MDM (Jamf) → Advanced Identity + compliance → Expert Fleet at scale → Extreme Security architect. Jamf Pro.
Basic Routing + switching → Intermediate VLANs + firewalls → Advanced SD-WAN → Expert Wireless + cloud → Extreme Architecture. CCNA → CCIE.
Basic Schema + queries → Intermediate Tuning + backup → Advanced Replication + HA → Expert Security + encryption → Extreme Cloud DB. Oracle OCP.
Basic Linux + Git → Intermediate CI/CD + scripting → Advanced Containers + IaC → Expert K8s + observability → Extreme Platform engineering. CKA/CKS.
Basic Linux + ops → Intermediate SLIs/SLOs → Advanced IR + observability → Expert Capacity + chaos → Extreme Platform reliability lead.
Basic Net + one cloud → Intermediate IAM + storage → Advanced Multi-service → Expert Cost + automation → Extreme Multi-cloud. AWS SAA-SAP, AZ-104.
Basic Broad tech → Intermediate Net + crypto → Advanced Sec Architecture → Expert Zero Trust + IAM → Extreme Enterprise architecture. CISSP-ISSAP.
Every card on this map links to actual learning content. Free tier covers the foundations.
Pick up where you left off — track progress across 396 modules, claim shareable certificates, and get the weekly threat-intel digest.
Continue with GoogleNew here? Create a free account → Already a member? Sign in →